gray-mueller / gray-mueller/restaurant-ordering-system-using-react-js
Enatega Admin Dashboard : Unauthorized Data Display on Admin Dashboard to new user logged-in.
- Dominant language
- TypeScript
- Stars
- 0
- Forks
- 0
- PR merge metrics
- No merged PRs in 30d
Description
Describe the bug
The admin dashboard displays data that is not relevant to the user's position, allowing users to view information they should not have access to. For example if a vendor logs-in to admin dashboard he should only be allowed to see the data relevant to his position not overall or un-necessary information.
To Reproduce
Steps to reproduce the behavior:
Go to 'Enatega Admin Dashboard'
Login as new user for example as new Vendor.
See error , now see admin dashboard displays data that is not relevant to the user's position, allowing users to view information they should not have access to.
Expected behavior
The dashboard should display only the data that is relevant to the logged-in user's role or position.
Users should not see data that belongs to other roles or departments.
Screenshots
Image Image
Desktop (please complete the following information):
OS: [e.g. Windows]
Browser [e.g. Chrome]
Version [e.g. Latest]
Contributor guide
Research direction
Start by reproducing the issue in the Enatega Admin Dashboard with a newly created Vendor account and compare the displayed data with the account's role. Trace the dashboard's role-based data loading and access checks; the work is done when users see only data relevant to their role and not information belonging to other roles or departments.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- react, typescript
- Domain
- authorization, frontend, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100